# cloud-gouv/securix

SécurixOS is a NixOS-based secure operating system tailored for small to medium-sized teams. It provides a minimal, hardened environment with strong isolation, reproducibility, and policy-driven configurations to ensure operational security and compliance.

Repository: https://github.com/cloud-gouv/securix
Canonical: https://ross.abutalabs.com/products/securix
Language: Nix
License Family: other
Last push: 2026-09-02T13:25:52+00:00

## Health v2 (maintenance only)
Score: 88/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 100, release rhythm 100, longevity 39
- inputs: {"age_days": 553, "days_push": 0, "days_rel": 2, "gap_med": 9, "n_releases_24m": 12}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1029, forks 48 (observed 2026-09-03T02:15:10.064831+00:00)

## What it is
SécurixOS is a NixOS-based hardened Linux distribution for secure workstations, developed by the French DINUM for sysadmin, office, and development use. It applies ANSSI hardening recommendations with TPM2, Yubikey, FIDO2 authentication, Secure Boot enrollment, and encrypted secrets management.

## Use cases
- set up a hardened secure workstation for sysadmins
- deploy reproducible NixOS machines with ANSSI-compliant hardening
- manage FIDO2 and Yubikey-based login and disk decryption
- enroll Secure Boot keys centrally with TPM2 support
- encrypt secrets with age or Vault across team machines
- provision secure laptops for small and medium teams

## When to choose
- you need ANSSI-aligned Linux hardening out of the box
- your team already uses NixOS and wants reproducible secure workstations
- you rely on TPM2, Yubikey, or FIDO2 for authentication and disk encryption

## When to avoid
- you need a production-ready, supported OS today (project is alpha)
- you do not use or want NixOS declarative configuration
- you need Windows/macOS or non-Linux environments
- you require a license-guaranteed distribution (no license declared yet)

## Facets
- artifact type: application
- maturity: experimental
- function: security, secrets-management, configuration-management
- domain: security, operating-systems, self-hosted
- platform: self-hosted
- tags: nixos, hardened-os, anssi, secure-boot, tpm2, yubikey, fido2, disk-encryption, secure-workstation, devops, linux

## Member repositories
- cloud-gouv/securix (main) score 88

## Provenance
- Observed fields: from GitHub, fetched 2026-09-03T02:15:10.064831+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T07:07:44.321154+00:00, confidence not recorded.
  - readme: https://github.com/cloud-gouv/securix (fetched 2026-09-03T02:15:10.064831+00:00, sha 3e74fd0111cb)
- Data as of 2026-08-30T08:39:29.467469+00:00.
